Index | Recent Threads | Unanswered Threads | Who's Active | Guidelines | Search |
World Community Grid Forums
Category: Retired Forums Forum: Member-to-Member Support [Read Only] Thread: WCG uses HTTPS 'CONNECT' method |
No member browsing this thread |
Thread Status: Active Total posts in this thread: 6
|
Author |
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
I'm currently trying to use WCG through a Squid proxy but I think it uses HTTPS 'CONNECT' method to encapsulate its data.
This method is known to have security issue: setting up a tunnel with an external server, an internal user could use virtually any type of programs (IM, P2P, etc). In fact, many http-tunnelling-through-CONNECT programs exist (for instance, hopster). Any suggestion? |
||
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
your could use http tunnel ng along with SocksCap V2, or ask your system admin to open the ports the gird agent uses..
|
||
|
Alther
Former World Community Grid Tech United States of America Joined: Sep 30, 2004 Post Count: 414 Status: Offline Project Badges: |
I'm currently trying to use WCG through a Squid proxy but I think it uses HTTPS 'CONNECT' method to encapsulate its data. This method is known to have security issue: setting up a tunnel with an external server, an internal user could use virtually any type of programs (IM, P2P, etc). In fact, many http-tunnelling-through-CONNECT programs exist (for instance, hopster). Any suggestion? The Agent has to use the HTTPS CONNECT method if you have a proxy set up. It's the only way to make an SSL connection through a proxy. I'm not sure what security issues you are talking about though. From the client side there shouldn't be any issues. The SSL connection is still made and the traffic flows between the client and server encrypted. The example you list is a potential issue from the firewall admin's perspecitve. Since by definition they're not alllowed to view HTTPS CONNECT traffic and thus can't stop anything from being tunneled through it. It can be filtered on the server and port if you like. Can you list your concerns in more detail?
Rick Alther
Former World Community Grid Developer |
||
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
I'm also the firewall admin :-)
And I hate to know that there are application tunnelling any type of traffic in HTTPS. In any case, I'm unable to pass WCG traffic through my proxy (Squid), peraphs because have I an antivirus (Trend IWSS) along the chain? |
||
|
Alther
Former World Community Grid Tech United States of America Joined: Sep 30, 2004 Post Count: 414 Status: Offline Project Badges: |
I'm also the firewall admin :-) And I hate to know that there are application tunnelling any type of traffic in HTTPS. You mean like a web browser? I still don't understand your concerns. It seems like you object to us sending the data back to our servers encrypted. This is done primarily so results can't be tampered with during communication. The reason admins have some worries about ANY secure connection is because malicious programs can pump data through it and they can't look at it. But that's true for any secure connection (HTTPS, SSH, any SSL/TLS connection, etc.), regardless if it's proxied or not. Either they allow it or the shut off all secure communication out of the network. Except for closed networks, I've never seen anyone shut down secure communications. If you're that worried about bad programs on your system, you can always set up the proxy to allow only certain endpoints so that you allow known traffic through. In any case, I'm unable to pass WCG traffic through my proxy (Squid), peraphs because have I an antivirus (Trend IWSS) along the chain? As for why it can't connect, AV shouldn't be the culprit. Does it intercept all outgoing traffic? I would think any AV software would simply allow HTTPS traffic to go through since it can't possibly check it for virus'. How about your proxy? What does it say regarding the connection? Does it deny it? Did you ever download a workunit? Did you set up the proxy information correctly in the Agent?
Rick Alther
Former World Community Grid Developer |
||
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
Ok, don't worry for my paranoic thoughts....
Now, I have no time to look in depth the problem with proxy. I disabled proxy for myself only and I'm running WCG without problems, because I like this project! We can close this thread. |
||
|
|